Privacy Policy - Gardeners Brent Cross
This Privacy Policy explains how Gardeners Brent Cross collects, uses, stores, and protects personal data when providing gardening services to customers in the area. It applies to all Gardeners Brent Cross customers in the local area, including anyone who enquires about, books, receives, or pays for our services. We are committed to handling personal data in a lawful, fair, and transparent manner in accordance with the UK GDPR and the Data Protection Act 2018.
1. Who We Are
Gardeners Brent Cross provides gardening and outdoor maintenance services to residential and commercial customers. In this policy, “we,” “us,” and “our” refer to Gardeners Brent Cross as the data controller for the personal information we collect and process in connection with our services.
We take data protection seriously and aim to ensure that all personal information is processed only where it is needed, kept secure, and retained only for as long as necessary.
2. Information We Collect
We may collect and process the following categories of personal data:
- Identity information such as your name and title.
- Contact information such as your address, email address, and telephone number.
- Service details such as the type of gardening work requested, appointment preferences, and service history.
- Billing and payment information such as invoice details and payment records.
- Communication records including messages, notes from calls, and correspondence relating to quotes, bookings, and service updates.
- Property and access information where required to carry out services safely and effectively, such as gate codes, access instructions, or relevant site notes.
- Technical information if you contact us through digital means, which may include basic device or usage data collected by standard website or email systems.
We do not seek to collect unnecessary personal data. Where special category data is not needed for the service, we do not request it. If such data is accidentally shared with us, we will only process it where lawful and appropriate to do so.
3. How We Use Personal Data
We use personal data for the following purposes:
- To respond to enquiries and provide quotations.
- To manage bookings, appointments, and service delivery.
- To communicate about schedules, changes, and service requirements.
- To issue invoices, process payments, and maintain financial records.
- To keep internal records of services carried out.
- To improve service quality and customer experience.
- To meet legal, accounting, and regulatory obligations.
- To handle complaints, disputes, or claims.
We only use personal data for purposes that are relevant to the services we provide or where we are legally required to do so.
4. Lawful Basis for Processing
Under UK GDPR, we must have a lawful basis for processing personal data. Gardeners Brent Cross relies on the following lawful bases depending on the context:
Contract
We process personal data when it is necessary to enter into or perform a contract with you. This includes providing quotations, confirming bookings, carrying out gardening services, and managing payments.
Legitimate Interests
We may process data where it is necessary for our legitimate business interests and where those interests are not overridden by your rights and freedoms. Examples include maintaining service records, improving our operations, preventing fraud, and managing customer communications.
Legal Obligation
Some data must be retained or processed to comply with legal obligations, such as tax rules, accounting requirements, and record-keeping duties.
Consent
Where we rely on your consent, we will make this clear at the point of collection. You may withdraw consent at any time where consent is the lawful basis for processing. Withdrawal will not affect processing carried out before consent was withdrawn.
5. Sharing Data and Processors
We may share personal data with trusted third parties where necessary to deliver our services or operate our business. These third parties act as processors or, in some cases, independent controllers.
- Payment providers who process transactions securely.
- Accounting and bookkeeping providers who help maintain financial records and comply with tax obligations.
- IT and communication service providers who support email, storage, scheduling, or record management systems.
- Professional advisers such as accountants or legal advisers where required.
- Public authorities where disclosure is required by law.
All processors are expected to handle personal data securely and only in accordance with our instructions, applicable law, and appropriate contractual protections. We do not sell personal data.
6. Data Retention
We keep personal data only for as long as necessary for the purposes for which it was collected, unless a longer retention period is required or permitted by law. Retention periods depend on the type of information and the reason it is held.
- Customer service records are generally retained for the duration of the working relationship and for a reasonable period afterwards.
- Financial and tax records are retained for the period required by law and standard accounting practice.
- Communication records may be kept for as long as needed to resolve queries, support future services, or evidence agreements.
- Consent-based records are retained only while consent remains valid or until the relevant purpose has ended.
When data is no longer needed, we will delete it securely or anonymise it where appropriate. We review retained data periodically to ensure it is not kept longer than necessary.
7. Data Security
We use reasonable technical and organisational measures to protect personal data against unauthorised access, loss, misuse, alteration, or disclosure. These measures may include access controls, secure storage, limited staff access, and careful management of records and devices.
While we take appropriate steps to protect data, no system can be guaranteed to be completely secure. We therefore encourage customers to share only the information that is necessary for us to provide services.
8. Your Rights
As a data subject under UK GDPR, you have rights in relation to your personal data. These include:
- Right of access – to request a copy of the personal data we hold about you.
- Right to rectification – to ask us to correct inaccurate or incomplete data.
- Right to erasure – to request deletion of your data in certain circumstances.
- Right to restrict processing – to ask us to limit how we use your data in certain situations.
- Right to object – to object to processing based on legitimate interests or direct marketing, where applicable.
- Right to data portability – to receive certain data in a structured, commonly used format where technically feasible.
- Right to withdraw consent – where processing is based on consent.
You also have the right to raise a concern with the UK Information Commissioner’s Office if you believe your data protection rights have been infringed. We encourage customers to contact us first so that we can try to resolve the issue promptly and fairly.
9. Data Sharing Outside the UK
In some cases, personal data may be stored or processed using service providers outside the UK. Where this happens, we will take appropriate steps to ensure that your data is protected in line with applicable data protection laws, including the use of suitable safeguards where required.
10. Children’s Data
Our services are generally intended for adults. We do not knowingly collect personal data from children unless it is necessary in connection with a customer request and is provided by an adult with responsibility for the relevant property or service arrangement.
11. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our services, legal obligations, or data processing practices. Any updated version will apply from the date it is published or otherwise made available. We recommend reviewing this policy periodically.
12. Summary of Our Approach
Gardeners Brent Cross processes personal data only when needed to deliver gardening services, manage customer relationships, meet legal obligations, and protect legitimate business interests. We keep data secure, retain it only for as long as necessary, and respect your rights under data protection law. Our commitment is to handle every customer’s information with care, transparency, and accountability.